Falhas do tipo CWE-120

3.164 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2024-48986HIGHAn issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byEPSS 0.5%CVE-2026-45811HIGHApache NimBLE: Buffer overflow in socket HCI transportEPSS 0.5%CVE-2024-29244MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /applEPSS 0.5%CVE-2024-48982HIGHAn issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byEPSS 0.5%CVE-2021-23159—A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability isEPSS 0.5%CVE-2025-46789MEDIUMZoom Clients for Windows - Classic Buffer OverflowEPSS 0.5%CVE-2020-37075HIGHLanSend 3.2 - Buffer Overflow (SEH)EPSS 0.5%CVE-2020-37070HIGHCloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)EPSS 0.5%CVE-2025-0689HIGHGrub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code executionEPSS 0.5%CVE-2023-50010HIGHFFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id fEPSS 0.5%CVE-2026-28925HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS TahoeEPSS 0.5%CVE-2026-84512HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2026-36228HIGHBuffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code viEPSS 0.5%CVE-2021-42757MEDIUMA buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated lEPSS 0.5%CVE-2026-76695MEDIUMUnauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2023-24548MEDIUMOn affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packetsEPSS 0.5%CVE-2026-88409HIGHFalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matriEPSS 0.5%CVE-2026-12328HIGHMemory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152EPSS 0.5%CVE-2024-50838MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. EPSS 0.5%CVE-2023-52729HIGHTCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of lEPSS 0.5%